No more typing reviews! Try our Samantha, our new voice AI agent.

Coverity Static vs ERPScan SMART Cybersecurity Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Coverity Static
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
43
Ranking in other categories
Static Application Security Testing (SAST) (12th)
ERPScan SMART Cybersecurity...
Average Rating
0.0
Number of Reviews
1
Ranking in other categories
Application Security Tools (40th)
 

Mindshare comparison

Coverity Static and ERPScan SMART Cybersecurity Platform aren’t in the same category and serve different purposes. Coverity Static is designed for Static Application Security Testing (SAST) and holds a mindshare of 2.5%, down 7.4% compared to last year.
ERPScan SMART Cybersecurity Platform, on the other hand, focuses on Application Security Tools, holds 0.7% mindshare, up 0.2% since last year.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Coverity Static2.5%
SonarQube13.3%
Checkmarx One8.8%
Other75.4%
Static Application Security Testing (SAST)
Application Security Tools Mindshare Distribution
ProductMindshare (%)
ERPScan SMART Cybersecurity Platform0.7%
SonarQube11.8%
Checkmarx One8.0%
Other79.5%
Application Security Tools
 

Featured Reviews

SP
Lead Information Security at GEP Worldwide at ReBIT
Helps us identify security vulnerabilities in the development phase and provides a plugin for the developer IDE
The initial setup is good. When I use the product to scan the code in the DevOps pipeline, the issue coverage can be greater, which can help speed up risk identification in the CI/CD pipeline. That is one area where improvement can be made. Corresponding steps can be taken for that. It integrates with most of the tools, like ticketing tools, configuration tools, Jenkins, and the pipeline. That is fantastic.
TO
Consulting Partner, Cyber Security Delivery - Africa at DeltaGRiC Consulting
Good core scanning, a helpful GDPR assessment template and very good technical support
The core scanning, the scanning process, has got a very nice pass management module. It's fantastic. The last time we did it, the customer was trying to make the SAP system match the GDPR process. We were able to use it for that benchmark. It was very important. The GDPR assessment template that is being used in the process application benchmark and analyzing landscape came in very handy. It was very useful because it also gave notifications.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the most valuable features is Contributing Events. That particular feature helps the developer understand the root cause of a defect. So you can locate the starting point of the defect and figure out exactly how it is being exploited."
"Provides software security, and helps to find potential security bugs or defects."
"The most valuable feature of Coverity is that it shows examples of what is actually wrong with the code."
"Coverity provides developers with a good, best practice, coding advice, and tracks risks of poor coding quality."
"It is a scalable solution."
"In my opinion, the most effective Coverity feature for identifying critical vulnerabilities is the extra checks, which offers deep analysis."
"It has the lowest false positives."
"I like Coverity's capability to scan codes once we push it. We don't need more time to review our colleagues' codes. Its UI is pretty straightforward."
"The core scanning, the scanning process, has got a very nice pass management module, and the GDPR assessment template that is being used in the process application benchmark and analyzing landscape came in very handy and was very useful because it also gave notifications."
"The core scanning, the scanning process, has got a very nice pass management module. It's fantastic."
 

Cons

"The product lacks sufficient customization options."
"The setup takes very long."
"Some features are not performing well, like duplicate detection and switch case situations."
"Its price can be improved. Price is always an issue with Synopsys."
"Coverity takes a lot of time to dereference null pointers."
"Sometimes it's a bit hard to figure out how to use the product’s UI."
"Coverity's implementation cycle is very slow when integrating changes, especially for problems related to event handling and memory leaks."
"The solution needs to improve its false positives."
"The solution is generally good, but it's not seamless."
"The anomaly detection could be improved."
 

Pricing and Cost Advice

"I would rate the pricing a six out of ten, where one is low, and ten is high price."
"The pricing is very reasonable compared to other platforms. It is based on a three year license."
"The tool was fairly priced."
"Offers varying prices for different companies"
"The licensing fees are based on the number of lines of code."
"The tool's price is somewhere in the middle. It's neither cheap nor expensive. I would rate the pricing a five out of ten."
"Coverity is very expensive."
"Coverity’s price is on the higher side. It should be lower."
Information not available
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
908,858 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
28%
Computer Software Company
9%
Financial Services Firm
7%
Comms Service Provider
5%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise6
Large Enterprise31
No data available
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What needs improvement with Coverity?
The price is a concern, and there are a lot of false positives coming through. Support with Coverity is adequate, but they take a longer time to respond. The core support is not straightforward, an...
Ask a question
Earn 20 points
 

Also Known As

Synopsys Static Analysis
No data available
 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
Wired
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Static Application Security Testing (SAST). Updated: August 2026.
908,858 professionals have used our research since 2012.